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DETAILED ACTION 

1 . A response was received on 21 January 2009. By this response, no claims have 
been amended, added, or canceled. Claims 1, 2, 4-17, 19-23, and 25-35 are currently 
pending in the present application. 

Response to Arguments 

2. Applicant's arguments filed 21 January 2009 have been fully considered but they 
are not persuasive. 

Regarding the rejection of Claims 1,2, 4-17, 19-23, and 25-35 under 35 U.S.C. 
103(a) as unpatentable over Macaulay, US Patent Application Publication 
2003/0135762, in view of Hrastar, US Patent 7042852, and with specific reference to 
independent Claims 1 and 19, Applicant again argues that neither Macaulay nor Hrastar 
discloses the state table as recited in the independent claims (pages 3-5 of the present 
response). More specifically, Applicant maintains "that the state data store of Hrastar 
does not disclose the MAC address parameter nor the further unrelated parameter" and 
that the state "only refers to 'whether or not the device has been seen before and 
whether or not the station is unauthenticated and unassociated, authenticated, 
authenticated and associated or unknown state information associated with the wireless 
computer network'" (page 4 of the present response, citing Hrastar, column 29, lines 12- 
17). Applicant further asserts that although "the Examiner is obviating [sic] the MAC 
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address parameter and the further unrelated parameter by using the station database", 
Claim 1 instead "recites that the state table (not a further table such as a station 
database) includes state information" including the MAC address and unrelated 
parameters (page 4 of the present response, emphasis Applicant's). However, the 
Examiner submits that the station database as disclosed by Hrastar, by itself (i.e. not in 
conjunction with the disclosed state data store), meets the claimed state table because 
it includes state information that includes all three of the MAC address parameter (see 
Hrastar, column 29, lines 5-1 1 , in particular lines 7-8, where the station database 
includes a device address, which is a MAC address, see column 26, lines 41-46, for 
example), the authentication status parameter (Hrastar, column 29, lines 5-1 1 , in 
particular line 8, where the station database includes "communications state" which 
corresponds to the claimed authentication status, noting also the description of what is 
encompassed by the "state" at column 29, lines 12-17, as previously cited and noted 
above by Applicant), and the further unrelated parameter (Hrastar, column 29, lines 5- 
1 1 , where the station database includes other parameters such as timestamps and byte 
counts). The Examiner thus submits that the station database itself corresponds to the 
claimed state table, as detailed above. 

Therefore, for the reasons detailed above, the Examiner maintains the rejection 
as set forth below. 
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Specification 

3. The objection to the specification for failure to provide antecedent basis for the 
claimed subject matter is withdrawn in light of Applicant's remarks more specifically 
pointing out antecedent basis support for the claimed subject matter is to be found (see 
pages 2-3 of the present response). 

Claim Rejections - 35 USC §112 

4. The rejection of Claims 1,2, 4-17, 19-23, and 25-35 under 35 U.S.C. 112, first 
paragraph, for failure to comply with the written description requirement is withdrawn in 
light of Applicant's remarks explicitly pointing out where written description support for 
the claimed subject matter is to be found in the present specification (see pages 2-3 of 
the present response). 

Claim Rejections - 35 USC § 103 

5. The following is a quotation of 35 U.S.C. 1 03(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 102 of this title, if the differences between the subject matter sought to be patented and 
the prior art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 
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6. Claims 1, 2, 4-17, 19-23, and 25-35 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Macaulay, US Patent Application Publication 2003/0135762, in view 
of Hrastar, US Patent 7042852. 

In reference to Claim 1 , Macaulay discloses a method for detecting unauthorized 
attempts to access a wireless data communication system, where the method includes 
forwarding one or more packets received by an access point to a computer that 
compares the format of the packets to a format specified by a protocol (see paragraphs 
0045-0046 and 0095-0107; note also paragraphs 0032-0035 and 0042 where the 
wireless network is monitored), and signaling an alert if the packets deviate from the 
protocol specified format (see paragraphs 0049-0050). However, Macaulay does not 
explicitly disclose maintaining a state table storing state information for the mobile units, 
where the state information is also used to signal an alert. 

Hrastar discloses a method in which a state table storing state information for 
mobile units is stored (column 28, line 64-column 29, line 4, where the data store 
includes a state data store and a station database; column 29, lines 5-17), where the 
state information includes at least a MAC address parameter, an authentication status 
parameter, and a further parameter unrelated to the MAC address parameter and 
authentication status parameter (column 29, lines 5-17, where the station database 
includes information including a device address, communications state, and other 
parameters, where the address is a MAC address, column 26, lines 41-46, the "state" 
corresponds to the claimed authentication status, and the timestamps and byte counts, 
for example, correspond to the claimed unrelated parameters), and an alert is signaled 
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if packets deviate from the stored state information (column 30, lines 35-43). Therefore, 
it would have been obvious to one of ordinary skill in the art to modify the method of 
Macaulay to include state information, in order to enhance network security (Hrastar, 
column 5, lines 21-22). 

In reference to Claim 2, Macaulay and Hrastar further disclose a header 
message portion and comparing the format of the header portion to the protocol 
specified format (see Macaulay, the table following paragraph 0094). 

In reference to Claim 4, Macaulay and Hrastar further disclose comparing format 
of a frame control field (see Macaulay, the table following paragraph 0094). 

In reference to Claims 5 and 6, Macaulay and Hrastar further disclose 
Management and Control frames (see Macaulay, the table following paragraph 0094; 
see also paragraph 0099). 

In reference to Claims 7 and 8, Macaulay and Hrastar further disclose comparing 
a WEP flag value (see Macaulay, paragraph 0104). 

In reference to Claim 9, Macaualay and Hrastar further disclose a protocol 
version (see, for example, Macaulay, paragraph 0083). 

In reference to Claims 10 and 1 1 , Macaulay and Hrastar further disclose source 
MAC addresses that are multicast and broadcast addresses (see Macaulay, paragraphs 
0124, 0127). 

In reference to Claims 12-15 and 17, Macaulay and Hrastar further disclose 
monitoring for a possible denial of service attack (Macaulay, paragraph 0106) and that 



Application/Control Number: 10/809,599 Page 7 

Art Unit: 2437 

the packets may contain unsupported values and lengths (Macaulay, paragraph 0107, 
for example). 

In reference to Claim 16, Macaulay and Hrastar further disclose detecting a 
spoofed MAC address (Macaulay, paragraphs 0095, 0101). 

In reference to Claim 19, Macaulay discloses a method for detecting 
unauthorized attempts to access a wireless data communication system, where the 
method includes forwarding one or more packets received by a mobile unit to a 
computer that compares the format of the packets to a format specified by a protocol 
(see paragraphs 0045-0046 and 0095-0107; note also paragraphs 0032-0035 and 0042 
where the wireless network is monitored), and signaling an alert if the packets deviate 
from the protocol specified format (see paragraphs 0049-0050). However, Macaulay 
does not explicitly disclose maintaining a state table storing state information for the 
mobile units, where the state information is also used to signal an alert. 

Hrastar discloses a method in which a state table storing state information for 
mobile units is stored (column 28, line 64-column 29, line 4, where the data store 
includes a state data store and a station database; column 29, lines 12-17), where the 
state information includes at least a MAC address parameter, an authentication status 
parameter, and a further parameter unrelated to the MAC address parameter and 
authentication status parameter (column 29, lines 5-17, where the station database 
includes information including a device address, communications state, and other 
parameters, where the address is a MAC address, column 26, lines 41-46, the "state" 
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corresponds to the claimed authentication status, and the timestamps and byte counts, 
for example, correspond to the claimed unrelated parameters), and an alert is signaled 
if packets deviate from the stored state information (column 30, lines 35-43). Therefore, 
it would have been obvious to one of ordinary skill in the art to modify the method of 
Macaulay to include state information, in order to enhance network security (Hrastar, 
column 5, lines 21-22). 

Claims 20-23 and 25-35 recite limitations corresponding to and similar to those 
recited in Claims 2 and 4-17, and are rejected by a similar rationale. 

Conclusion 

7. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time 
policy as set forth in 37 CFR 1 .136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within 
TWO MONTHS of the mailing date of this final action and the advisory action is not 
mailed until after the end of the THREE-MONTH shortened statutory period, then the 
shortened statutory period will expire on the date the advisory action is mailed, and any 
extension fee pursuant to 37 CFR 1 .136(a) will be calculated from the mailing date of 
the advisory action. In no event, however, will the statutory period for reply expire later 
than SIX MONTHS from the mailing date of this final action. 
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Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Zachary A. Davis whose telephone number is (571 )272- 
3870. The examiner can normally be reached on weekdays 8:30-6:00, alternate 
Fridays off. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Emmanuel Moise can be reached on (571) 272-3865. The fax phone 
number for the organization where this application or proceeding is assigned is 571- 
273-8300. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information 
system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 

/ZAD/ 

Examiner, Art Unit 2437 

/Emmanuel L. Moise/ 
Supervisory Patent Examiner, Art 
Unit 2437 



